Hackers now exploit critical Gitea flaw in code injection attacks
Reported exploitedGiteaOur summary
CISA has confirmed that attackers are actively using a critical code injection vulnerability in Gitea to deploy cryptocurrency mining malware on self-hosted servers. Tracked as CVE-2026-60004, this flaw allows authenticated users with repository write access—and effectively any unregistered attacker due to default open registration—to execute arbitrary shell commands through the diffpatch API endpoint. The agency added the issue to its Known Exploited Vulnerabilities catalog and mandated federal civilian executive branch agencies apply fixes by August 28. Users should upgrade to Gitea version 1.27.1 immediately to mitigate these attacks.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.